Windows Named Pipe Access to ADFS/WID Database by Uncommon Process

Alert on named pipe creation to the AD FS WID SQL query endpoint when initiated by uncommon processes.

FreeReviewedSigma · Medium · v2
Product
windows
Category
pipe_created
Author
Roberto Rodriguez @Cyb3rWard0g (SigmaHQ), DRL 1.1
Published
2021-10-08
Updated
2026-07-31

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags creation of a named pipe connection targeting the AD FS Windows Internal Database (WID) query pipe (\MICROSOFT##WID\tsql\query). Such access can be used to retrieve AD FS configuration data and related sensitive information that may support token-signing or authentication workflows. It relies on Windows telemetry from named pipe creation events and examines the creating process image to reduce matches from expected service binaries.

Related detections9 linkedT1005 — drag to rearrange
Suspicious BoryptGrab Infostealer Staging Directory (via file_event)
Suspicious Astaroth Spambot Browser Profile Staging Directory (via file_event)
Suspicious Browser and Wallet Credential Theft via JavaScript Stealer
Suspicious WhatsAppBackup Data Staging Archive Creation
Suspicious Environment File Credential Search via findstr (via process_creation)
Suspicious RDP Bitmap Cache Temp Files Written by mstsc in Rogue RDP Campaign (via file_event)
Suspicious Azure CLI Disk Snapshot and Copy for Data Theft
Windows Script Interpreter Launching trufflehog or gitleaks Credential Scanner
Linux Script Interpreters Spawning Credential Scanners (trufflehog, gitleaks)
Windows Named Pipe Access to ADFS/WID Database by Uncommon Process
Pivot detection · T1005 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.